User Tools

Site Tools


paloaltonetworks:configuration:multi_vsys

Multi-VSYS

Collapsing Multi-Vsys

Collapsing multivsys firewalls controlled by Panorama into single vsys firewalls. In this case, the two VSYS were external and internal were effectively a perimeter firewall and a core firewall.

  1. Perform pre-cutover config checks.
    1. Backup the configuration of each firewall and Panorama. Also take device state exports of each firewall.
    2. Get an operational baseline - what VPN tunnels are up/down, how many sessions are running, how many GP users are connected to each gateway,etc.
    3. If migration of configuration has happened in lab, make sure the migrated configuration file you are about to import has the correct interface and HA IP addresses set as well as management interface certificates, etc.
  2. Perform a failover to the passive node, disable HA config sync and disable pre-emption. Commit this change to both firewalls.
  3. On the primary device (now passive) - We should revert all config to local config (i.e. detach from Panorama) and upload and load the new configuration file that has merged the two VSYS and commit. At this point HA should still be 'working' but the two firewalls will have vastly different configs.
  4. We can now failover to primary (with the new config).
  5. Test to make sure that the merged VSYS configuration is correct. If not, failback to the secondary while you troubleshoot futher/rollback.
  6. On the secondary device (now passive) - We should revert all config to local config (i.e. detach from Panorama) and enable HA config sync.
  7. On the primary devices (now active) - enable HA config sync. This means the secondary device should get config from the primary device. If not, push from the primary device.
  8. You may want to disable multi-vsys on the firewalls before importing to Panorama.
  9. On Panorama, remove the firewalls from the existing DG's and templates.
  10. Import the fireawlls into Panorama. Clean up configs to replace the local configs with Panorama shared or Global Template configs. - For GT config - we should just move this template to the top of the new stack during the push step on the migrating from local to Panorama step.
paloaltonetworks/configuration/multi_vsys.txt · Last modified: by 127.0.0.1